Skip to content

Latest commit

 

History

History
48 lines (36 loc) · 2.61 KB

BUILDAVM.md

File metadata and controls

48 lines (36 loc) · 2.61 KB

VM Installation

Windows

Despite having bought retail copies of Windows and Office, they aren't appropriate for using within a malware analysis environment and will frequently complain and/or de-activate themselves, because of this it's necessary to force Windows & Office to permanently activate and not do silly things like constantly ping license servers or otherwise attempt to contact the outside world.

vmcloak configures the first ethernet device, don't change this unless you remember to change it back to previous settings. to access the internet add a second NAT adapter in VirtualBox.

Basic gist of it is:

  • Install Microsoft products
  • Stop them complaining and contacting the internet
  • Install misc. crapware
  • Disable unnecessary stuff, reduce memory profile
  • Make it look like a real computer
  • Optimise the VM image

The steps are:

Now you should have a Windows 7 VM that can open Office documents, play flash & java apps, run most applications etc. Disabling some services makes packet captures cleaner because the VM won't make requests to the internet or LAN while idle.

VirtualBox

  • vboxmanage internalcommands sethduuid win7x64.vdi